The traffic is blocked/allowed at our network layer before being routed to the droplet. The rules are easily configurable through the control panel and API. You can also specify Droplets (individual or tagged) and our recently new Load Balancers as the targets.
You can also layer multiple firewalls on top of one another if you want to apply specific firewall rules to only a specific set of Droplets/LBs
The Intro tutorial we have is great for details: https://www.digitalocean.com/community/tutorials/an-introduc...
Feel free to reach out to us if you have any more specific questions. :)